PEN-200 Buffer Overflow Fundamentals Practice Question
You are exploiting a 32-bit Windows application that reads a line of input into a 256-byte stack buffer using a vulnerable function. After sending a payload of 300 'A' characters, the application crashes and the debugger shows EIP contains 0x41414141. You need to determine the exact number of bytes from the start of the buffer to the saved return address. Which approach is most appropriate?
⚠ Common exam trap
The trap here is assuming that the saved return address is always exactly 4 bytes after the buffer, ignoring possible saved registers or alignment padding that can shift the offset.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Send a unique, non-repeating pattern of characters (e.g., generated by pattern_create) and calculate the offset from the value in EIP.
The pattern-based approach is the de facto standard for determining the offset to the return address in a buffer overflow. By sending a unique cyclic pattern, the overwritten EIP value directly maps to a specific offset, which can be calculated with pattern_offset. This method is reliable because it does not rely on assumptions about stack layout and works even when the buffer size is not exactly known.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incrementally increase the number of 'A' characters until the application crashes, then subtract 4 from the total length.
Why it's wrong here
Incrementing 'A's only tells you the minimum length to crash, not the exact offset to EIP. Subtracting 4 assumes the saved return address is exactly 4 bytes after the buffer, but stack layout may include other saved registers or padding. This method is imprecise and can lead to an incorrect offset, causing the exploit to fail.
- ✗
Send a payload of 256 'A's followed by 4 'B's and check if EIP contains 0x42424242.
Why it's wrong here
This assumes the buffer is exactly 256 bytes and the saved return address immediately follows it. However, the stack may contain other data such as saved frame pointer or alignment padding. Without knowing the exact stack layout, this test may not yield 0x42424242, leading to confusion. The pattern method avoids such assumptions.
- ✗
Use a debugger to inspect the stack and manually count the bytes between the start of the buffer and the saved return address.
Why it's wrong here
Manual counting in a debugger is error-prone and time-consuming. While it can work, it is not the most efficient or reliable method. The pattern-based approach automates the process and reduces human error. In a real penetration test, efficiency and accuracy are critical, so the pattern method is preferred.
- ✓
Send a unique, non-repeating pattern of characters (e.g., generated by pattern_create) and calculate the offset from the value in EIP.
Why this is correct
A non-repeating pattern allows you to correlate the overwritten EIP value with the exact offset in the buffer. Tools like pattern_create.rb from Metasploit generate such a pattern, and pattern_offset.rb reveals the distance. This is the standard method to find the precise offset to the return address in a stack-based buffer overflow.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.